Description
Key Skills: Detection Engineering, SIEM, EDR, MITRE ATT&CK Framework, Splunk, CrowdStrike Falcon, Microsoft Defender, Threat Detection, Security Operations, Sigma Rule Authoring
Good to Have Skills: Experience with threat intelligence integration and threat-driven detection strategies. Understanding of risk-based alerting and alert prioritization techniques. Offensive security certifications such as OSCP, CRTE, or equivalent. Familiarity with MITRE ATLAS and AI/ML threat detection concepts. Scripting experience in Python for automation, log analysis, or tooling development. Experience in creating security standards, logging frameworks, or governance documentation.
Roles & Responsibilities:
- Translate offensive security findings, penetration test reports, and red team assessments into actionable detection use cases.
- Develop, validate, and maintain detection rules across SIEM and EDR platforms for comprehensive security coverage.
- Build correlation-based detections using Splunk and native detections within platforms such as CrowdStrike Falcon and Microsoft Defender.
- Validate detections against live telemetry and ensure production readiness for deployment in enterprise environments.
- Collaborate with offensive security teams to ensure accurate detection coverage for identified attack techniques and methodologies.
- Maintain and improve MITRE ATT&CK coverage across the organization to enhance threat detection capabilities.
- Identify detection gaps and recommend appropriate monitoring controls to strengthen security posture and visibility.
- Continuously assess and improve visibility into emerging threats and attack techniques through proactive monitoring strategies.
- Work with engineering teams to ensure required log sources and telemetry are available for effective detection development.
- Develop investigation guides and runbooks for security operations teams to improve incident response effectiveness.
- Support MSSP and SOC teams by improving alert quality and reducing false positives through optimized detection logic.
- Collaborate with incident response teams to enhance detection logic based on lessons learned from security investigations.
- Maintain a centralized detection rule repository with proper documentation and version control for governance purposes.
- Manage and prioritize the detection engineering backlog based on risk, threat intelligence, and offensive security findings.
- Report detection coverage and security monitoring effectiveness to stakeholders through measurable metrics and performance indicators.
Experience Required: 3+ years of experience in Detection Engineering, Security Operations, Threat Detection, or related cybersecurity roles with hands-on experience writing and maintaining production-grade detection rules